Article 93 of Regulation (EU) 2024/1689 — Power to request measures. Official text, practical interpretation, key obligations and compliance implications.
Official Text Summary
Article 93 of Regulation (EU) 2024/1689 (the EU AI Act) sits in Chapter IX, Section 5 — the section that gives the Commission, acting through the AI Office, exclusive supervisory powers over providers of general-purpose AI (GPAI) models. Within that section it is the third and most consequential rung of an escalating enforcement ladder: Article 91 lets the Commission request documentation and information, Article 92 lets it conduct evaluations of a model, and Article 93 lets it demand that the provider actually do something about what those steps reveal. Unlike the market-surveillance powers elsewhere in Chapter IX, these powers are not exercised by national authorities: for GPAI models, the Commission is the single enforcer across the Union.
Article 93(1) authorises the Commission, where necessary and appropriate, to request a provider to do one of three things: (a) take appropriate measures to comply with the provider obligations set out in Articles 53 and 54; (b) implement mitigation measures, where an evaluation carried out under Article 92 has given rise to serious and substantiated concern of a systemic risk at Union level; or (c) restrict the making available on the market of the model, or withdraw or recall it. The three limbs form their own internal escalation, from ordinary compliance through targeted mitigation to removal of the model from the Union market.
The two remaining paragraphs build in de-escalation. Under Article 93(2), before any measure is requested, the AI Office may open a structured dialogue with the provider. Under Article 93(3), if a provider of a GPAI model with systemic risk offers commitments to implement mitigation measures, the Commission may by decision make those commitments binding on the provider and declare that there are no further grounds for action — closing the procedure without a formal measure ever being imposed.
What This Means in Practice
Formally, limb (a) reaches any GPAI model provider that falls short of its Article 53 obligations (technical documentation, information to downstream providers, copyright policy, training-content summary) or Article 54 (authorised representative for non-EU providers). In practice, the centre of gravity is the small group of providers whose models are classified as carrying systemic risk under Articles 51 and 52 — the presumption threshold being training compute above 10²⁵ FLOPs — because the mitigation and recall limbs are tied to systemic-risk findings from Article 92 evaluations.
For those providers, Article 93 is where supervision acquires teeth. A documentation request is an administrative burden; an evaluation is scrutiny; a request for measures is an order with a fining mechanism behind it. Refusal exposes the provider to fines under Article 101 of up to 3% of worldwide annual turnover or €15 million, whichever is higher — and non-compliance with the request is a fining ground of its own, independent of the underlying breach.
The limb with the widest blast radius is (c). A restriction, withdrawal or recall of a frontier model is existential for its provider, but it does not stop there: every downstream AI system built on that model inherits the disruption. An organisation that has integrated a systemic-risk model into its products has, in effect, a regulatory dependency it does not control. Prudent downstream providers and deployers therefore track the regulatory standing of their upstream model and address the recall scenario contractually — continuity commitments, migration assistance, notification duties.
The commitments mechanism in Article 93(3) will do much of the real work. It mirrors the commitments decisions of EU competition law: the provider offers a package of mitigations, the Commission makes it binding, and both sides avoid a contested measure. A worked example: an Article 92 evaluation of a frontier model raises serious and substantiated concern that its capabilities could meaningfully assist the creation of biological threats. The AI Office opens a structured dialogue; the provider offers staged access controls, enhanced refusal training and third-party red-teaming on a defined timetable; the Commission makes those commitments binding and closes the file. No recall, but an enforceable safety upgrade.
Key Obligations
- Respond to a request for measures within its terms. An Article 93(1) request is not advisory; ignoring it is independently finable under Article 101.
- Keep the underlying Article 53 and 54 obligations demonstrably met — technical documentation, downstream information, copyright policy, training-content summary, and an authorised representative where required — since limb (a) converts any persistent gap into an enforceable order.
- For systemic-risk providers, maintain the Article 55 apparatus (model evaluations, adversarial testing, incident reporting, cybersecurity): these are the measures a mitigation request will in practice demand more of.
- Engage with the structured dialogue. Article 93(2) exists to resolve concerns before formal measures; treating it as adversarial discovery wastes the cheapest exit.
- Consider commitments early. A well-designed Article 93(3) commitments package closes the procedure with a declaration that no further grounds for action exist.
- Downstream operators: no direct Article 93 duty, but real exposure to limb (c) — monitor the upstream model's standing and provide for restriction, withdrawal or recall in contracts.
Relationship to Other Articles
Article 93 completes the enforcement chain of Chapter IX, Section 5. Article 88 establishes the Commission's exclusive enforcement competence for GPAI providers; Article 89 provides monitoring; Article 90 channels alerts of systemic risk from the scientific panel — often the trigger for everything that follows. Article 91 (documentation and information) and Article 92 (evaluations) are the investigative rungs immediately below Article 93, and an Article 92 finding of serious and substantiated concern is the express precondition for a mitigation request under 93(1)(b). Article 94 guarantees the procedural rights of the economic operators concerned.
The substantive obligations that a request enforces live in Articles 53 and 54 (all GPAI providers) and Article 55 (providers of models with systemic risk), with classification and designation governed by Articles 51 and 52. Adherence to a code of practice under Article 56 is the practical way a provider demonstrates compliance — and therefore the cheapest insurance against ever receiving a request. The fining backstop is Article 101. For the wider context of GPAI regulation, see the GPAI hub; for penalty exposure across the Act, see Article 99.
Compliance Timeline
The Regulation entered into force on 1 August 2024. The substantive GPAI obligations that Article 93 enforces — Articles 53 to 55 — have applied since 2 August 2025. The Commission's enforcement powers under Chapter IX, Section 5, including the power to request measures, apply from 2 August 2026, together with the Article 101 fining power over GPAI providers.
The 2026 Digital Omnibus did not touch this track: it deferred the high-risk obligations of Annex III and Annex I to 2 December 2027 and 2 August 2028 respectively, but left the GPAI framework and its enforcement dates intact. For providers of systemic-risk models, the practical preparation is straightforward to state and demanding to do: keep Articles 53–55 evidence current, adhere to a code of practice, rehearse the structured-dialogue scenario, and have a commitments strategy ready before the AI Office ever calls.
Official AI Act Compliance Deadline Calendar
Updated · Sources: Regulation (EU) 2024/1689 and the 2026 Digital Omnibus on AI.
| Obligation | Applies to | Original date | New date | Status | Countdown | Legal basis |
|---|---|---|---|---|---|---|
| Prohibited Practices (Art. 5) | All providers and deployers | active | — | AI Act Art. 5 | ||
| GPAI Rules (Chapter 5) | GPAI model providers | active | — | AI Act Art. 51-56 | ||
| Commission Enforcement Powers over GPAI | GPAI model providers | active | — | AI Act Art. 88-94, 101 | ||
| Transparency Obligations (Art. 50) | Providers and deployers of chatbots, generative, emotion recognition systems | active | — | AI Act Art. 50 | ||
| New Art. 5 Prohibition (CSAM / non-consensual intimate imagery) | Providers and deployers of generative AI systems | active | — | AI Omnibus 2026 Art. 5 | ||
| AI-Generated Content Marking (pre-existing systems) | Providers of generative AI systems on the market before 2 Aug 2026 | active | — | AI Act Art. 50(2) — transitional | ||
| Regulatory Sandboxes | National competent authorities | deferred | — | AI Omnibus 2026 Art. 57 | ||
| High-risk AI — Annex III (standalone) | Providers of standalone Annex III systems | deferred | — | AI Omnibus 2026 Art. 6(2) | ||
| High-risk AI — Annex I (embedded) | AI embedded in Annex I regulated products | deferred | — | AI Omnibus 2026 Art. 6(1) |
⬇ Download JSON · CC BY 4.0
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
Three things, in escalating order of severity: that a provider of a general-purpose AI model take measures to comply with its obligations under Articles 53 and 54; that it implement mitigation measures where an Article 92 evaluation has raised serious and substantiated concern of a systemic risk at Union level; or that it restrict the making available on the market, withdraw, or recall the model.
Directly, providers of general-purpose AI models — in practice above all providers of models with systemic risk, since the mitigation and recall powers are tied to systemic-risk findings. Indirectly, every downstream provider and deployer whose AI systems are built on such a model: a restriction or recall of the upstream model cascades through every system that depends on it.
The Commission can impose fines under Article 101 of up to 3% of worldwide annual turnover or €15 million, whichever is higher. Non-compliance with a request for measures is itself a fining ground, separate from the underlying breach. The market-restriction, withdrawal and recall option in Article 93(1)(c) remains available as the ultimate enforcement step.
Yes. Under Article 93(3), if the provider offers commitments to implement mitigation measures addressing the systemic risk, the Commission may by decision make those commitments binding and declare that there are no further grounds for action — a settlement mechanism familiar from EU competition law.
Stay ahead of AI Act changes
Get compliance alerts when deadlines or obligations change.
No spam. One-click unsubscribe.
Take compliance further with the AI Act Academy
Templates, training modules, and live Q&A — everything needed to implement AI Act compliance.